[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[cobalt-users] SMTP server down, NOT ANY MORE!!!!



In case anyone is interested, I believe my SMTP down issue is resolved. It was the RAQ, it was our host-site-company. I received the email below from them late this afternoon, and since they changed their side we have been FANTASTIC. What they changed has fixed so many things, such as: 1) my email was logging on very slowly, send and receive, now it is instantaneous 2) ftp logon was very slow, even from an NT box sitting right next to the RAQ, like 5 seconds just to logon, another 3 to get the directory listing, now it is instantaneous

I have not lost SMTP for about 5 hours now, I had been losing it every 30-60 minutes.

The list of what is working better goes on. Here's what was found

Danny,

I think I found the problem. It looks like your RAQ server is acting as it's own DNS server. The access-list on our router didn't allow your server to do DNS lookups to other DNS servers on the Internet. We were assuming you were using our DNS servers of 216.182.xxx.xxx and 216.182.xxx.yyy I've opened up your access list slightly to allow UDP traffic from port 53 on any server on the Internet to reach your server on ports higher than 1023. This is the default behavior of many DNS servers, to use high UDP ports for receiving answers to DNS queries. Once I added that line, all your services sped up a lot. I think this fixed the problem. Let me know. Below is your current access list:
....
If you want to make it a little more secure, you can set Bind to use a query source port of 53 (which I'll have to reconfigure the access list again to allow) so all the answers to DNS queries return on port 53. If you want it even more secure, setup your DNS server to use forwarders and point it at our DNS servers. I'll then be able to block the traffic above 1023 (originating from port 53) to your RAQ server since you'll be asking our DNS servers to resolve everything.

Hope this can help someone else out there, at least it will be in the archives now.

Thanks for all the assistance, a special thanks to Joe at hardynet who generously offered to lend personal assistance.

Great group you are!!!
Jale, Danny is real life.